Skills Summary
Program / Project Management
Full Program / Project lifecycle including program strategy, scoping, functional analysis, proof of concept testing, budgeting, planning, managing and implementing projects. Vendor and third party management.
IT Governance / Information Security
• Enterprise security management, governance, vulnerability and threat analysis/testing.
• Lead compliance and security audit reviews; investigation and incident response.
• IT security strategy, policies, standards, guidelines definitions, development and implementation of plans.
• Security risk assessment of information systems, governance, processes, controls, data and physical facilities, new technology projects, business ventures affecting technology and business globally as per the Guidelines of ISO 27001, ISO 17799 & ISO 38500. Security architecture design, engineering and review.
IT / Networking Technologies
• Data Centers: TIA 942, Tier-III and Tier-IV Design, Management, Standard specifications, Requirements, Compliance and Operations of large Enterprise and Commercial Data Centres.
• Routing: RIP, IGRP, OSPF, EIGRP, BGP, MPBGP, MPLS, LDP/TDP Frame mode, MPLS TE, MPLS QOS, L3 VPN on Cisco Products
• Switching: Transparent Bridging, VLAN, Inter-VLAN Routing on Cisco Products.
• Security: IKE, IPSEC, MD5, SHA, DES, 3DES, AH, ESP, SSL, ASA, IPS, PIX, VPN Concentrator, AAA, Netscreen ISG-2000
• NMS: CA Spectrum, E- Health, Solarwind, MRTG, WhatsUp
Education & Qualification
Masters in Computer Engineering : National University of Sciences & Technology College of E & ME (NUST), Rawalpindi, Pakistan
Masters in Information Security : National University of Sciences & Technology,
Military College of Signals, Rawalpindi, Pakistan
B. E. Electrical (Communications) : College of Engineering & Technology,
(Grade 79.4%) A/1st (first Position) Mirpur, AJK.
Key Certifications
Project Management Professional (PMP) : Project Management Institute
CGEIT – Certified in Governance of Enterprise IT : ISACA, USA
ITILv3 Foundation : Exin
ISO 27001 – Certified ISMS Implementer : Exin
Certified Data Centre Professional (CDCP) : EPI, Singapore
Certified Data Centre Specialist (CDCS) : EPI, Singapore
Certified Data Centre Expert (CDCE) : EPI / ICOR
Career History
GM of IT, Enterprise IT & DC Operations, PTCL, (Etisalat - Pakistan), Islamabad (June 07, 2009 to Date)
• Program Manager: Converting a large basic IT Infrastructure into Dynamic and Business Enabler infrastructure.
• Prepared and presented a comprehensive 3 years IT Strategy Program for Modernizing the IT Services as per ITILv3.0 and IT Governance Framework and gained approval from Etisalat Advisory Team and CIO Etisalat-Pakistan.
• Business Process mapping and automation to ensure that IT shall be kept aligned to ensure availability, reliability, integrity and security of business functions and streamlining revenue values.
• Preparing compendium for Data Centre Profiles including Security and operational policies, control procedures and respective business process mapping.
• Working on IT Governance Strategy for Enterprise IT Operations & Controls based on CoBit 4.1.
• Involved in establishing organizational structure on the basis of COBIT and business processes.
• Definition of KPIs for Staff and regulating Workflows and Business Process Mapping for Enterprise.
• Directly Reporting to CIO and Leading a Team of 92 professionals (Senior Managers, Managers, Engineers and Technicians) and ensuring 24/7/365 IT operations and support across the country for over 400 locations.
• Member of IT Steering Committee for devising and deriving IT strategy plan for 1 year, 3 and 5 years. In addition to the management of programs governed by IT.
• Chairman Technical Committee for Projects of IT and Member Technical Committee for Special Telecom Projects with budget of over PKR 50 Million.
• Responsible for CAPEX and OPEX planning and approval for IT Department. The Currently supervised CAPEX / OPEX exceed PKR 2000 Million.
• Devising and maintaining SLAs and OLAs with external and internal stakeholders for smooth and proper operations of e-business and IT systems and infrastructure.
• Managing NOC, SOC and DOC with 24/7/365 monitoring, reporting, ticket tracking and automated escalation(s), to ensure proactive smooth operations and business services across over 400 locations.
• Worked on a USD 5.5 Million Project as Program Manager and Project Director for expansion and upgradation of Existing Billing and Customer Care System of PTCL (up gradation and business focused enhancement in applications and back end databases, migration to oracle 10G for seamless DR Operation with Implementation of RAC). Active Projects under supervision are having budget volume of over USD 20 Millions.
• Project Director for Establishment of TIER – iii Data Centers as per TIA 942 Standard:
(Responsibilities included from concept to completion of Data Centre, PTCL Headquarters, Islamabad).
o Design, Establishment and Management for PTCL Nerve Centre (CDDT DATA CENTRE), with an area of over 15000 sq ft as per TIA 942, Tier iii– iv compliance and guidelines.
o Data Centre Migration, relocation and consolidation from existing IT Equipment Facility / Rooms to fully managed and dynamically controlled Data Centre.
o Migration of Data Centre, including Complete Billing System, ERP, CRM, Intranet, Information Security Appliances, BI Systems, Exchange Data Collectors to the new facility.
o Designed, delivered and Management of 02, Tier iii Certified, Commercial Data Centers (greater than 15000 sq-ft) for offering, colocation and hosted services to external customers.
o These Data Centers are now only Tier iii certified Data Centers in Pakistan
• Project Director for Infrastructure Monitoring Project (NOC)
o The Project Covers Performance, Status Monitoring and Fault Analysis of IT Equipment, Networks, Databases, Service Management and applications.
o The CA E-Health and E-Spectrum is being deployed for active monitoring and implementation of ITILv3 Process Framework for Services, Network, Systems, Storage, EMS, WILY, Service Desk & Service Catalog.
• Project Director for IP Based Unified Call Centre
o Revamping of current deployed CC systems which have numerous limitations such as decentralized operations, single non overlapping solution for all different contact centers thus not making effective use of resources, no redundancy and failover at PSTN level resulting in single point of failure, no load balancing facility, no multimedia support, manual outbound dialing etc
o Preparation of RFP to Provide advanced integrated contact services in a reliable environment to PTCL customers.
o Integration of IPCC with Siebel CRM, which is also being rolled out in parallel.
o The business need of the hour is therefore to switch to a unified technologically advanced solution so that business can be supported in best possible manner
• Project Director for IT Fabric as per Tier-iii compliance
o Data Center network re-design; designed as 10G ready, three layered architecture (Access, Aggregation & Core) and unified fabric (FCOE, Virtualization) with Cisco Nexus 7k, 5k and 2k Solution.
o Flexibility and modularity has been the key component of architecture to cater upcoming requirements upto 05 years.
• Project Director for Could Computing Environment for Business and R & D
o Working on strategy for virtualization of IT Infrastructure to ensure optimal utilization of IT environment
o Providing “on the fly” IAAS, PAAS and SAAS Services to business, software development industry and Research & Development communities across the Country.
Senior Manager IT / (Networks, Security, Technical Support), IT Department, PTCL, (Etisalat - Pakistan) Islamabad (February 2008 to June 06, 2009)
Job Responsibilities carried out:
• Prepared, presented and got approval from Executive / Advisory members for the IT Security Policies and IT Strategic Planning.
• Service Management as per the ITIL framework, standardization of processes for enterprise IT Operations
• Project Manager Info Sec Infrastructure (Etisalat - Pakistan)
o Reporting to Executive Management, senior member of Team responsible for providing security governance, guidance, project management and consultancy including engagement and presentation to senior levels of the Business and IT.
o Designing of Information Security Infrastructure, which included deign of network architecture, system design, IT Governance principles, incident management, disaster recovery sites /plans and guidelines to ensure minimum downtimes for IT framework and services.
o Leading the Team to embed security architecture and engineering into the enterprise IT architecture framework
o Managing and negotiating vendor professional consultancy services to ensure that they meet project deliverables and milestones in a timely manner. Defined statements of works and requirements. Monitoring activities and deciding work priorities
o Established, defined, developed documents and implementation of information security guidelines, policies, procedures and processes according to company policy and industry best practices (such as ISO27001 & ITIL v3 Service Management Practices)
• Project Manager LAN Revamp @ PTCL Headquarters, Islamabad
o Reporting to Executive Vice President and General Manager ITIO, leading Team for revamping the complete LAN with higher grade equipment to fulfill the requirements of over 1500 users.
o Project developed and designed to meet the intents of high availability, secure and flexible network for Headquarters. Deployment of Cisco 4500 series switches at all 4 Blocks in two layer topology to fulfill the theme.
o Project cost was PKR 60.17 million.
• Managed Nationwide Enterprise PTCL network with more than 370 sites, as well as leading a Team of IP network and technical support Engineers to ensure availability of services and constant network support by 24/7.
• Designed and implemented monitoring of audit mechanisms to ensure compliance with those policies. Communication of IT Security Governance, IT Risk Analysis, and preparation of Root Cause Analysis as an ingredient of Incident Management Plans. Communication of risk management, IT Security Audit plans and strategies.
• Technical lead for design and implementation of Perimeter security project, successfully deployed ISS Proventia IPS and ISS Proventia Network Mail Security system.
• Responsible for Networks and IT Security meeting with technical and operational standards including Change, Incident and Problem Management.
• Analyzing new applications, identifying potential security concerns and developing techniques that can be used to diminish identified risks by implementation of recommendations.
Sr. Consultant (IT) / Project Manager Information Security, Qualitas Consulting and Training Company, Kuwait (Jan 2007 to December 2007)
Job Responsibilities:
• Extensively involved in network planning, high and low level design and solutions to major upcoming enterprise LAN/WAN and network security projects.
• Planning, designing and consolidating Data Center for clients.
• Defining, implementing and evaluating SLAs, SOPs, RFPs and Network/Security policies and procedures for the enterprise network.
• Ensuring security policies and procedures are implemented effectively, firewalls are put into practice and maintained correctly, implementation and management of IPS and IDS, monitoring and reviewing of security logs, ensuring that network designs are meeting with security policy.
• Planning developing and implementing information security policies, standards and guidelines for authorized and secure communications based on ISO 27001 / ISO/ BS 17799.
• Designing of IT infrastructure solutions based on core routers (Cisco 7200 series) / switches (4500 Series), VoIP gateways, firewalls (PIX 535/ASA), IDS/IPS (4400 Series) meeting with recognized encryption technology standards.
Information Security Manager, Telematix Corp, Islamabad, Pakistan (Jan 2003 – Jan 2007)
Job Responsibilities:
• Supporting project initiatives and development of cost breakdowns for systems solution issues.
• Advising and consulting internal clients responsible for the architecture, design, implementation, and deployment of infrastructure and applications on appropriate security controls to manage risk and meeting compliance with ISO standards.
• Research and evaluate new technologies, security risks, threat and solutions for architect reliance and integrity by managing security risks and follow-through implementation.
• Carried out comprehensive analysis of the inherent weaknesses in the network stacks and operating systems resulting in their vulnerability to denial of service attacks. (Five Research Papers accepted and presented at various International Conferences and Forums)
• Definition of key test scenarios and completion of verification testing to ensure solution is complete and meets the business requirements
• Conceded entire exercise to develop a Strategic Information Management (SIM) plan for District Government, Lahore, Pakistan.
• Analyzing wireless network protocol stacks for performance and security strengths. Worked comprehensively on WLAN Standards IEEE 802.11, Port Based Security Standard (IEEE 802.1X) and Enhanced Security Standard for Wireless Networks (IEEE802.11i) under the supervision of Prof. Dr. Muid Mufti. Pioneered in pronouncement of the security loopholes and vulnerabilities in recent IEEE 802.1X and IEEE 802.11i standards.
Instructor, Institute of Communication Technologies, PTCL, (Aug 2003 – August 2008)
Teaching graduate level courses to MS Telecom Engineering and conducting corporate trainings of PTCL officers and staff in the area of Broadband Solutions, Network Security Solutions and Emerging Technologies as a part time instructor.
Research Associate: Engineer, Military College of Signals, Rawalpindi (Aug 2002 – To Jan 2003)
Carried out in-depth analysis of the inherent weaknesses in Windows based Operating Systems, Network Stacks and Wireless Solutions. Trace back and audit of IT Systems, vulnerability assessment, penetration testing and enhancement in hardening the Telecom Infrastructure. Major work was classified.
Research Associate, NIIT, Rawalpindi, Pakistan (Aug 2001 – Aug 2002)
Worked as a Research Associate on the award winning Pakistan Academic Intranet project carried out by NUST. The project to interconnect 48 public and private sector universities spread all over Pakistan. Project received USD 0.7 million for pilot implementation and subsequent expansions.
Consultancy Services, Komax Advance Technology, Kuwait (Jun 2000 – Aug 2000)
Provided consultancy services to the Amiri Diwan (Equivalent to Presidency) in Kuwait for installation of information systems and computing infrastructure based on analog modems and routing for some remote locations.
Incharge Networkers, Al-Khair University, AJK (Jun 1999 – Jun 2000)
Installed fully functional Local Area Networks at the premises of an Infantry Battalion of Pakistan Army in Okara.
Journal Publications (Research)
• M.S Khalid, M. Umar. Ilyas, M. Saqib Sarfraz, A. Ajaz, “Bhattacharyya Coefficient in Correlation of Gray Scale Images”, Journal of Multimedia, Academy Publisher, Finland. (March 2006).
• M. Junaid, Muid Mufti, M.Umar Ilyas, “Vulnerabilities of IEEE 802.11i Wireless LAN CCMP protocol”, Transaction of Engineering, Computing and Technology, Enformatika Society, PP 228 – 233, Enformatika VII, ISSN 1305-5313, February 2006.
Conference Publications (Research)
• M. Umar Ilyas, Muid Mufti, Raja Iqbal, M.J Hussain, Salil Kanhere, “INDICT – INtrusion Detection, Identification, Containment & Termination”, International Conference On Computing & Informatics, ICOCI-2006, Kuala Lumpur, Malaysia. (6th – 8th June 2006)
• M. J Hussain, Muid Mufti, M. Umar Ilyas, “Imperfect Counter Mode Utilization – IEEE 802.11i WLAN”, IASTED International Conference on Networks and Communication Systems, NCS-2006, Chiang Mai, Thailand. (29th – 31st March 2006)
• M. J Hussain, Muid Mufti, M. Umar Ilyas, “Vulnerabilities of IEEE 802.11i Wireless LAN CCMP Protocol”, Enformatika International Conference on Computer Science, (ENFORMATIKA, Volume 11, ISBN 975-00803-0-0), ICCS-2006, Prague, Czech Republic. (24th – 26th February 2006)
• M. S Khalid, M. Umar Ilyas, et.al, “Kullback-Leiber divergence measure in Correlation of Gray-Scale Objects”, International Research Conference on Innovations in Information Technology, IIT-2005, Dubai, UAE. (26th – 28th September 2005)
• Muid Mufti, M. Umar Ilyas, M. AB Ilyas, “Modelling and Analysis of IEEE 802.11b Networks”, International Research Conference on Innovations in Information Technology, IIT-2005, Dubai, UAE. (26th – 28th September 2005)
• M. S.Khalid, M. Umar Ilyas, et. al, “Performance of a Similarity Measure in Grayscale Image Matching” IEEE International Conference of Emerging Technologies, ICET 2005, Islamabad, Pakistan. (17th – 18th September 2005)
• M. Umar Ilyas, Muid Mufti et.al “Effects of Fragmentation on IEEE 802.11b WLANs”, IASTED International Conference on Communication and Computer Networks, CCN-2004, MIT, Cambridge, USA. (8th -10th November 2004)
• M. A. B Ilyas, M.Umar Ilyas, et.al, “Network Modeling Language- Standardization of Symbols for Network Design, Visualization and Documentation” International Research Conference on Innovations in Information Technology, IIT-2004, Dubai, UAE. (4th – 6th October 2004)
• Muid Mufti, M. Umar Ilyas, “Empirical Modeling of IEEE 802.11b WLAN”, IASTED International Conference on Modeling, Simulation & Optimization, MSO-2004, Hawaii, USA. (17th – 19th August 2004)
• M. A. B Ilyas, M. Umar Ilyas, M. Saeed, Aysha Anwar “Tabeeb Online - Web Based Tele-Consultation & Patient Information Access”, presented at Informatics 2004, Kuala Lumpur, Malaysia. (27th – 30th July 2004)
• M. Umar Ilyas, “Operational Bounds of IEEE 802.11b Networks”, Dependable Systems and Networks, DSN – 2004, Florence, Italy. (29th June – 1st July). First time contribution from Pakistan in 34 years of conference.
• Muid Mufti, M. Umar Ilyas, “Performance Analysis of MAC Layer in IEEE 802.11 Networks”, First IFIP Conference on Wireless and Optical Communication Networks, WOCN-2004, ISSN 1811-3923, pp 90 – 93, Muscat, Oman. (7th – 9th June 2004)
• A.B. Ilyas, M. Umar. Ilyas, K. Rizwan, R. Ahmad, “Actor Centric Use-Case Analysis and Modeling”, poster paper in proceedings of INMIC2001, LUMS, Lahore, Pakistan. (December 2001).
• A.B. Ilyas, M. Umar. Ilyas, Z. Mustafa, “War in Cyberspace”, poster paper in proceedings of INMIC2001, LUMS, Lahore, Pakistan. (December 2001).
Other Technical Expertise / Certifications / Trainings
• Microsoft Certified System Engineer (MCSE)
• Cisco Certified Network Associate (CCNA)
• Cisco Certified Design Associate (CCDA)
• Cisco Certified Internet work Expert (CCIE, SP) written exam
• HP Certified Network Connectivity Professional
• Hacking Forensic Investigation (Qualified the training at TDI, Kuwait)
• Ethical Hacking (Qualified the training at TDI, Kuwait)
• CDMA 2000 Voice Network Optimization from Qualcomm University
• NPA (Network Performance Analysis) from Qualcomm University
• EVDO (EVolution Data Optimized) from Qualcomm University
• Trainings on OPM3 Assessment for Project Management Auditing
• Workshop on Network Security by NSP, Cisco Systems, Pakistan
Professional Memberships
• Project Management Institute (PMI), USA
• EPI, Australia
• Information Security Audit and Control Association (ISACA), USA
• Qualcomm University, USA
• Microsoft Technet
• Cisco
Current Targets
• Currently working to gain Program Management Professional PgMp.
Miscellaneous
• Providing consultancy services at various locations including GCC Countries and Pakistan for:
o IT Infrastructure Development, Data Center Shell, IT Fabric, Audit and Compliance
o Network and Security Architecture
o Managed Services Solutions
o Development of corporate IT Strategy with road map and action plan
o Preparation of operational procedures as per the guidelines of ITIL, ISO2000, 27001, BCP and DR Planning
• Attended various conferences, workshops and seminars on a variety of topics related to the communications, routing and switching trends, security and information technology.
• Sporting activities include football, badminton and hiking.
References
• Will be furnished upon request